Job Title: IAM/C-IAM integration expert
Department: Tribe Core Capabilities (CARDIF IT Corporate) - SEC4APP domain, Frontdesk Squad
About Business line/Function:
BNP Paribas Cardif is the insurance subsidiary of BNP Paribas. We are a worldwide leader of the Credit Protection Insurance market with strong positions in savings and protection insurance in more than 30 countries in Europe, Asia and Latin America.
Position Purpose:
Support Cardif international in IAM/C-IAM onboarding.
Responsibilities
Direct Responsibilities
- Design & Implement SSO solutions using SAML 2.0 and OpenID Connect (OIDC) across internal and external applications.
- Configure, maintain, and optimize Keycloak realms and clients (confidential, public, bearer‑only) to meet business SSO requirements.
- Create and manage protocol mappers, role‑to‑group mappings, and attribute‑release policies in Keycloak to ensure correct claim propagation.
- Integrate third‑party IdPs (Azure AD, Okta, ADFS, Google, etc.) and service providers (SPs) via SAML metadata exchange and OIDC discovery.
- Develop and maintain automation scripts (Terraform, or Helm) for repeatable Keycloak deployments in Kubernetes or VM environments.
- Perform security reviews and hardening of authentication flows (e.g., signing/encryption algorithms, token lifetimes, PKCE, JWS/JWE).
- Troubleshoot authentication failures, analyze SAML assertions and OIDC ID/access tokens using tools like SAML‑Tracer, jwt.io.
- Document architecture, runbooks, and SOPs for onboarding new applications and de‑provisioning legacy services.
- Collaborate with development, DevSecOps, and compliance teams to align IAM practices with GDPR, SOC 2 and internal policies.
- Provide on‑call support for critical authentication incidents; lead post‑mortems and drive continuous improvement.
Contributing Responsibilities
- Design & Implement SSO solutions using SAML 2.0 and OpenID Connect (OIDC) across internal and external applications.
- Configure, maintain, and optimize Keycloak realms and clients (confidential, public, bearer‑only) to meet business SSO requirements.
- Create and manage protocol mappers, role‑to‑group mappings, and attribute‑release policies in Keycloak to ensure correct claim propagation.
- Integrate third‑party IdPs (Azure AD, Okta, ADFS, Google, etc.) and service providers (SPs) via SAML metadata exchange and OIDC discovery.
- Develop and maintain automation scripts (Terraform, or Helm) for repeatable Keycloak deployments in Kubernetes or VM environments.
- Perform security reviews and hardening of authentication flows (e.g., signing/encryption algorithms, token lifetimes, PKCE, JWS/JWE).
- Troubleshoot authentication failures, analyze SAML assertions and OIDC ID/access tokens using tools like SAML‑Tracer, jwt.io.
- Document architecture, runbooks, and SOPs for onboarding new applications and de‑provisioning legacy services.
- Collaborate with development, DevSecOps, and compliance teams to align IAM practices with GDPR, SOC 2 and internal policies.
- Provide on‑call support for critical authentication incidents; lead post‑mortems and drive continuous improvement.
Technical & Behavioral Competencies
- Identity Protocols: SAML 2.0 (metadata, assertions, bindings), OpenID Connect (Authorization Code, Implicit, Hybrid, PKCE)
- Keycloak: Realm & client setup, authentication flows, custom SPI extensions, admin REST API, theme customization
- Programming / Scripting: Java (for custom Keycloak providers), Bash for automation, Groovy (optional)
- Infrastructure as Code: Terraform, Helm charts, Docker/Kubernetes (deployment of Keycloak)
- Security: JWT signing/encryption, X.509 certificates, OAuth 2.0 scopes, token revocation, MFA integration (TOTP, WebAuthn)
- Networking & Web: HTTPS/TLS, reverse proxies (NGINX, HAProxy, Apache), load balancers, DNS
- Monitoring & Logging: Prometheus/Grafana, ELK stack, Keycloak event listeners
- Version Control & CI/CD: Git, GitLab/GitHub Actions, Jenkins, Argo CD
- Documentation: Confluence, Markdown, Swagger/OpenAPI (for custom endpoints)
Specific Qualifications:
- Professional Experience: 5–10 years in IAM, SSO, or security engineering with a focus on SAML/OIDC implementations.
- Keycloak Expertise: Proven track record configuring and scaling Keycloak in production (≥ 2 years).
Skills Referential (Required knowledge, skills and abilities)
Technical Skills:
- Identity Protocols
- Keycloak
- Programming / Scripting
- Infrastructure as Code
- Security
- Networking & Web
- Monitoring & Logging
- Version Control & CI/CD
- Documentation
Behavioral Skills:
- Strong analytical mindset,
- ability to work cross‑functionally and mentor junior staff.
Transversal Skills:
- excellent written/oral communication,
Education Level: Bachelor’s degree in computer science, Information Security, or related field or equivalent professional experience
Location: Chennai
About BNP Paribas Group:
BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.
About BNP Paribas India Solutions:
Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.
Commitment to Diversity and Inclusion
At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.